Impact
Northstar (dromara/northstar) versions 9.1.1 and earlier improperly expose the embedded H2 database console. The authentication interceptor only protects the /northstar/ path, leaving the /h2-console endpoint unprotected. The H2 database defaults to the sa user with an empty password, allowing any network‑reachable attacker to reach the console without credentials and to execute arbitrary system commands via the CREATE ALIAS statement, which runs arbitrary Java code in the application context. This flaw provides immediate remote code execution with full system access, compromising confidentiality, integrity, and availability of the affected environment.
Affected Systems
The vulnerable product is Dromara Northstar quantitative trading platform, versions up to and including 9.1.1. Any deployment that has the H2 console enabled and is reachable over the network is susceptible, regardless of other application users or roles. The flaw is not limited to local hosts; any attacker able to reach the console endpoint can exploit it.
Risk and Exploitability
The vulnerability lacks a published CVSS or EPSS score in the provided data, but the exposed console with default credentials and the ability to run arbitrary commands through SQL create alias indicates a severity higher than medium. The attack can be carried out remotely over the network without prior authentication, so the risk is high. Although the vulnerability is not currently listed in the CISA KEV catalog, the absence of KPIs does not diminish the exploitation potential. An attacker can directly compromise the host running the Northstar instance, gaining full control, and the exploit requires only network access to the /h2-console endpoint.
OpenCVE Enrichment